CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-46938
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm rq: fix double free of blk_mq_tag_set in dev remove after table load fails When …

Feb 27, 2024
CVE-2024-25840
7.5 HIGH

In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download …

Feb 27, 2024
CVE-2024-24323
7.2 HIGH

SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java …

Feb 27, 2024
CVE-2024-27508
7.5 HIGH

Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.

Feb 27, 2024
CVE-2024-26142
7.5 HIGH

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This …

Feb 27, 2024
CVE-2024-25398
7.5 HIGH

In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service.

Feb 27, 2024
CVE-2024-27507
7.5 HIGH

libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.

Feb 27, 2024
CVE-2024-25723
8.8 HIGH

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on …

Feb 27, 2024
CVE-2024-0819
7.3 HIGH

Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges …

Feb 27, 2024
CVE-2024-0551
7.1 HIGH

Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted …

Feb 27, 2024
CVE-2023-51747
7.1 HIGH

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of …

Feb 27, 2024
CVE-2024-0197
7.8 HIGH

A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via …

Feb 27, 2024
CVE-2023-7016
7.8 HIGH

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local …

Feb 27, 2024
CVE-2023-5993
7.8 HIGH

A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level …

Feb 27, 2024
CVE-2021-46936
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: fix use-after-free in tw_timer_handler A real world panic issue was found as follow in …

Feb 27, 2024
CVE-2023-7165
7.5 HIGH

The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors …

Feb 27, 2024
CVE-2023-6585
7.5 HIGH

The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as …

Feb 27, 2024
CVE-2023-6584
7.5 HIGH

The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.

Feb 27, 2024
CVE-2023-50379
8.8 HIGH

Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster …

Feb 27, 2024
CVE-2024-0759
7.5 HIGH

Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, they …

Feb 27, 2024
CVE-2024-25711
7.5 HIGH

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to …

Feb 27, 2024
CVE-2024-24100
8.3 HIGH

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.

Feb 27, 2024
CVE-2024-24096
7.8 HIGH

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.

Feb 27, 2024
CVE-2024-22917
8.6 HIGH

SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

Feb 27, 2024
CVE-2024-27356
7.5 HIGH

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 …

Feb 27, 2024
CVE-2024-22544
8.0 HIGH

An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.

Feb 27, 2024
CVE-2023-36237
8.8 HIGH

Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

Feb 26, 2024
CVE-2024-26455
7.5 HIGH

fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.

Feb 26, 2024
CVE-2024-25768
7.5 HIGH

OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.

Feb 26, 2024
CVE-2023-52474
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests hfi1 user SDMA request processing has …

Feb 26, 2024
CVE-2019-25162
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are …

Feb 26, 2024
CVE-2019-25160
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), …

Feb 26, 2024
CVE-2024-27081
7.2 HIGH

ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 …

Feb 26, 2024
CVE-2024-27454
7.5 HIGH

orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.

Feb 26, 2024
CVE-2024-27359
7.5 HIGH

Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects …

Feb 26, 2024
CVE-2024-24714
7.2 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.

Feb 26, 2024
CVE-2024-23839
7.1 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap …

Feb 26, 2024
CVE-2024-23837
7.5 HIGH

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This …

Feb 26, 2024
CVE-2024-23836
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft …

Feb 26, 2024
CVE-2024-23835
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing …

Feb 26, 2024
CVE-2024-23605
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-23496
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-22873
8.1 HIGH

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers …

Feb 26, 2024
CVE-2024-22201
7.5 HIGH

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it …

Feb 26, 2024
CVE-2024-21836
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-21825
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to …

Feb 26, 2024
CVE-2024-21802
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-1889
8.8 HIGH

Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated …

Feb 26, 2024
CVE-2024-1876
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /psubmit.php. …

Feb 26, 2024
CVE-2024-1710
8.8 HIGH

The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the onAjaxAction function action in …

Feb 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.